
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Run ucss with grunt.
If you haven't used grunt before, be sure to check out the Getting Started guide.
From the same directory as your project's Gruntfile and package.json, install this plugin with the following command:
npm install grunt-ucss --save-dev
Once that's done, add this line to your project's Gruntfile:
grunt.loadNpmTasks('grunt-ucss');
If the plugin has been installed correctly, running grunt --help
at the command line should list the newly-installed plugin's task or tasks. In addition, the plugin should be listed in package.json as a devDependency
, which ensures that it will be installed whenever the npm install
command is run.
The task can do two things; Analyze html+css using ucss and print out any unused selectors in the grunt log and use that information to create new clean
In your project's Gruntfile, add a section named ucss
to the data object passed into grunt.initConfig()
.
grunt.initConfig({
ucss: {
target: {
options: {
whitelist: ['.some-ok-selector'],
auth: null
},
pages: {
crawl: 'http://localhost/crawlstart',
include: ['http://localhost/extra-not-reachable-by-crawl']
},
css: ['http://localhost/styles.css']
}
}
})
Type: Array
of String
Default value: []
An array of selectors that should be 'white listed' meaning will not be listed or cleaned away even though it isn't used.
Type: Object
Default value: null
Let's you specify authentication to use. See ucss auth documentation for more details
Type: String
Default value: []
Specify a html-file to start crawling
Type: Array
of String
Default value: []
Any extra pages not included in the crawl.
Specify what css files to analyze
In lieu of a formal styleguide, take care to maintain the existing coding style. Add unit tests for any new or changed functionality. Lint and test your code using grunt.
So, I started up this task and then abandoned it for a while... I've released this initial version just to get a version ppl can start using. I will add more test-cases and so on later on, and if you got an idea or feature to add just tell med :)
FAQs
Run ucss with grunt.
The npm package grunt-ucss receives a total of 0 weekly downloads. As such, grunt-ucss popularity was classified as not popular.
We found that grunt-ucss demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.